﻿using System;
using System.Data;
using System.Configuration;
using System.Linq;
using System.Web;
using System.Xml.Linq;
using System.Data.SqlClient;

/// <summary>
/// Summary description for UserDAO
/// </summary>
public class UserDAO :SQlHelper
{
    public bool ValidateUser(string username, string password)
    {
        using (SqlConnection conn = GetConnectionString())
        {
            bool isValid = false;
            SqlCommand cmd = new SqlCommand("SELECT username FROM Users WHERE username = '"+username+"' AND Password = '"+password+"' ", conn);
            cmd.CommandType = CommandType.Text;            
            SqlDataReader reader = cmd.ExecuteReader();
            if (reader.HasRows)
            {
                isValid = true;
                reader.Close();
                conn.Close();
            }
            return isValid;
        }
    }
}
